David Chiang

243 posts

David Chiang

David Chiang

@david942j

CTF @ 217 & HITCON

Katılım Haziran 2015
91 Takip Edilen1.7K Takipçiler
David Chiang retweetledi
Angelboy
Angelboy@scwuaptx·
Excited to share our research on Kernel Streaming! We discovered several vulnerabilities in it that we used at Pwn2Own this year. Check it out: devco.re/blog/2024/08/2…
English
5
125
326
45.3K
David Chiang retweetledi
Orange Tsai  🍊
Orange Tsai 🍊@orange_8361·
Thanks @BlackHatEvents for the #BHUSA acceptance! It's pure web hacking research this time! 🔥 However, I'm still not sure if I can enter the US or not. In advance, I reapplied for the VISA and had the interview in March. Two months have passed, and my case is still under review. I really want to be back on stage. Is there any effort or help I can try? 😫
Orange Tsai  🍊 tweet media
English
20
54
473
100.7K
卡嗯
卡嗯@tmt514·
有什麼辦法可以根治沒事就想吃炸雞或雞排的念頭🫣
中文
4
0
3
318
David Chiang
David Chiang@david942j·
I'm probably lagged but just found this website is pretty good for learning kernel exploitation! pawnyable.cafe
English
1
13
90
10.7K
David Chiang
David Chiang@david942j·
@BrieflyX Good idea, and seems it's good to collect all kinds of solutions
English
0
0
1
0
Zhongyu Pei
Zhongyu Pei@BrieflyX·
@david942j I vote for atoms since many teams solved it via unintended bugs. I would like to see how to trigger the real deadlock XD.
English
1
0
1
0
JinBlack (Mario Polino)
JinBlack (Mario Polino)@JinBlackx·
@david942j If you alloc and then map multiple pages (size > 0x1000) by munmapping pages singularly you get the ref counter below 1. So the cur_pool structure is set free. But the file descriptor is still alive. Then when that chunk is reallocated, by mapping you get a crash (and the flag)
English
1
0
3
0
Zhongyu Pei
Zhongyu Pei@BrieflyX·
I solved spark in HITCON CTF 2020. The CONFIG_SLAB_FREELIST_HARDENED made it hard to exploit via a single UAF and costs much of my time. Eventually another out-of-bound bug in query algorithm saved me. Thanks to @david942j for 2 interesting kernel chals! github.com/BrieflyX/ctf-p…
English
3
8
47
0
David Chiang
David Chiang@david942j·
@JinBlackx I didn't know there's a UAF bug until now.. And yes there are deadlock bugs.
English
2
0
0
0
JinBlack (Mario Polino)
JinBlack (Mario Polino)@JinBlackx·
@david942j quick question about atoms. Is the intended solution a real deadlock? Because we exploited a UAF to crash the kernel. I am not sure the UAF was the intended solution by looking at your code.
English
1
0
1
0